Input validation error in Open vSwitch - CVE-2020-35498

 

Input validation error in Open vSwitch - CVE-2020-35498

Published: February 10, 2021 / Updated: April 7, 2023


Vulnerability identifier: #VU50603
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-35498
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing network packets. A remote attacker can send specially crafted traffic to the system and perform a denial of service (DoS) attack.


Affected software

Open vSwitch
Gentoo Linux
SUSE Linux Enterprise Server
Ubuntu
openEuler
Fedora
openvswitch (Red Hat package)
openvswitch (Debian package)
ovn2.11 (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch2.13 (Red Hat package)
openvswitch-common (Ubuntu package)
libopenvswitch-2_11-0
openvswitch-debugsource
openvswitch-debuginfo
openvswitch
libopenvswitch-2_11-0-debuginfo
openvswitch-help
openvswitch-devel
net-misc/openvswitch
dpdk
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Enterprise Linux Fast Datapath
Red Hat OpenShift Container Platform

How to mitigate CVE-2020-35498

Install update from vendor's website.

openvswitch (Red Hat package) - update to 2.9.9-1.el7fdp
openvswitch (Debian package) - update to 2.10.7+ds1-0+deb10u1
ovn2.11 (Red Hat package) - update to 2.11.1-57.el7fdp
openvswitch2.11 (Red Hat package) - addressed in versions 2.11.3-83.el8fdp, 2.11.3-86.el7fdp
openvswitch2.13 (Red Hat package) - addressed in versions 2.13.0-79.5.el8fdp, 2.13.0-81.el7fdp
openvswitch-common (Ubuntu package) - addressed in versions 2.5.9-0ubuntu0.16.04.3, 2.9.8-0ubuntu0.18.04.2, 2.13.1-0ubuntu0.20.04.4, 2.13.1-0ubuntu1.3
libopenvswitch-2_11-0 - update to 2.11.5-3.9.1
openvswitch-debugsource - update to 2.11.5-3.9.1
openvswitch-debuginfo - update to 2.11.5-3.9.1
openvswitch - update to 2.11.5-3.9.1
libopenvswitch-2_11-0-debuginfo - update to 2.11.5-3.9.1
openvswitch - update to 2.12.0-11
openvswitch-help - update to 2.12.0-11
openvswitch-devel - update to 2.12.0-11
openvswitch-debuginfo - update to 2.12.0-11
openvswitch-debugsource - update to 2.12.0-11
openvswitch - update to 2.15.0-1.fc33
net-misc/openvswitch - update to 2.17.6
Red Hat OpenShift Container Platform - update to 4.7.4
dpdk - update to 20.11-1.fc33

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins